CVE-2025-69223

Executive Summary

AIOHTTP versions 3.13.2 and earlier are vulnerable to a zip‑bomb denial‑of‑service attack. An attacker can send a highly compressed HTTP request that, when decompressed by the server, consumes excessive memory and crashes the host. The issue is fixed in 3.13.3 and is not listed in CISA KEV.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2026-01-05T22:15:53.017 - Last Modified: 2026-09-09T13:18:08.777

Original Description: AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Versions 3.13.2 and below allow a zip bomb to be used to execute a DoS against the AIOHTTP server. An attacker may be able to send a compressed request that when decompressed by AIOHTTP could exhaust the host's memory. This issue is fixed in version 3.13.3.

"Simply put, you believer that things or people make you unhappy, but this is not accurate. You make yourself unhappy."

— Wayne Dyer
Source: NVD